US Department of Defense STIG for SQL Server 2022
US Department of Defense STIG for SQL Server 2022

SQL Server Security Hardening Guide Using the DoD STIG Checklist

| 0 comments

Security on your SQL Server is important. That doesn’t need any explaining. But where do you start when evaluating the security of your SQL Server? If you are like me, and probably for many DBAs, that’s the hardest part. You know security matters, but without a structured baseline, it’s easy to overlook configuration issues that could expose your environment to unnecessary risk. Starting with a proven checklist gives you a clear way to identify gaps before they become problems. And how do you even implement the principle of least privilege on the instance and database level?

And how do you even implement the principle of least privilege on the instance and database level?

Well, we’re lucky that the U.S. Department of Defense has provided a Security Technical Implementation Guide (STIG) for SQL Server, along with many other technologies. It gives you a well-established security baseline that you can use to evaluate your SQL Server environment, whether you’re working with an on-prem deployment, a virtual machine, or even a lab environment. Even if you’re not in a government-regulated organization, the STIG is still a practical reference for identifying security gaps and strengthening your SQL Server configuration.

You need two things: the SQL Server 2022 STIG and the STIG viewer.

Download the STIG file

Download the guide here. Search for SQL Server and select Microsoft SQL Server 2022 STIG. Click the Download button to, well, download the zipped STIG file.

You don’t have to extract the zip file. We’ll load the whole zip file on the viewer in the next step.

Install the STIG viewer

Download the STIG viewer here: https://www.cyber.mil/stigs/srg-stig-tools/. Download the msi installer called STIG Viewer 3.7.0-Win64 msi. Extract the installer package. Unfortunately, macOS is not supported. This is a Windows-only app.

Click Yes to allow the app to make changes to your device.

There is no wizard steps to follow. Upon clicking Yes, the STIG Viewer should be installed right away.

Load the STIG file

To load the STIG zip file (the first zip file we downloaded above) in the viewer, click the Open button in the STIG Viewer section (top panel). That will load both the STIG for SQL Server Instance and Database in the viewer.

You may want to add STIG to the Library so you don’t have to reload the STIG documentation each time. You can simply add the whole zip file.

If the STIG docs will not automatically appear after they are added in the library, close the app and open it again.

You can always go to the Dashboard by clicking the Home buttom at the upper right-hand navigation menu. Click the STIG Viewer button to open the STIG docs.

You can now then view the rules contained in the STIG docs. Select the Microsoft SQL Server 2022 Intance to view the rules for the instance (and Database for the database-level checks).

We will create our custom Checklist in our follow up post. We’ll also customize it so you can have a version of this STIG for your organization.

Author: Marlon Ribunal

I'm here to learn and share things about data and the technologies around data.

Leave a Reply

Required fields are marked *.


This site uses Akismet to reduce spam. Learn how your comment data is processed.

Verified by MonsterInsights